Einar Lonn discovered that under certain conditions bind9, a DNS server,may use cached data before initialization. As a result, an attacker cantrigger and assertion failure on servers under high query load that doDNSSEC validation.

For the stable distribution (squeeze), this problem has been fixed inversion 1:9.7.3.dfsg-1~squeeze6.

For the testing distribution (wheezy), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed inversion 1:9.8.1.dfsg.P1-4.2.

We recommend that you upgrade your bind9 packages.

Further information about Debian Security Advisories, how to applythese updates to your system and frequently asked questions can befound at: http://www.debian.org/security/